Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle EufyManage Eufy Security (HomeBase S380 + SoloCam S340/E340) from the `eufy` CLI—capture snapshots, forward alarms to the Tuya hub, and change guard/alarm modes through eufy-security-ws.
567 -
majiayu000 Bundle PassComplete guide for using pass, the standard Unix password manager. Use this skill whenever the user asks about pass, password-store, managing passwords from the terminal, GPG-encrypted passwords, setting up pass for the first time, inserting or generating passwords, syncing a password store with git, using pass-otp for TOTP codes, importing passwords from another manager, or any task involving the `pass` CLI. Trigger on phrases like "set up pass", "add a password to pass", "sync my password store", "generate a password", "pass git", "pass-otp", "pass-import", or any variation.
567 -
majiayu000 Bundle SiemMonitors and analyzes security events and logs for real-time threat detection and incident response.
567 -
majiayu000 Bundle SnykSnyk security scanning for dependencies. Use for vulnerability scanning.
567 -
majiayu000 Bundle SoarImplements Security Orchestration, Automation, and Response for blue-team incident handling.
567 -
majiayu000 Bundle Soc2Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). Use this skill whenever a user mentions SOC 2, Trust Services Criteria, SOC 2 Type 1 or Type 2, audit readiness, compliance gaps, control documentation, evidence collection, vendor risk questionnaires, or anything related to AICPA service organization controls. Trigger even for adjacent topics like "we need to get audited", "a customer asked for our security report", "writing an information security policy", or "preparing for an audit". Covers gap analysis, policy writing, control documentation, audit evidence preparation, and vendor risk reviews for organizations at any maturity level — from first-time startups to seasoned compliance teams.
567 -
majiayu000 Bundle WispDrafts a Written Information Security Program compliant with Massachusetts 201 CMR 17.00 and supplementary frameworks (GDPR, CCPA, HIPAA, GLBA, PCI-DSS). Produces a board-ready regulatory document covering coordinator designation, risk assessment, safeguards, training, incident response with breach notification, and vendor oversight. Use when an organization handles personal information of MA residents and needs a standalone WISP for regulatory examination or executive approval.
567 -
majiayu000 Bundle SenseiIteratively improve skill frontmatter compliance using the Ralph loop pattern. USE FOR: run sensei, sensei help, improve skill, fix frontmatter, skill compliance, frontmatter audit, improve triggers, add anti-triggers, batch skill improvement, check skill tokens. DO NOT USE FOR: creating new skills (use skill-authoring), writing skill content, token optimization only (use markdown-token-optimizer), or non-frontmatter changes.
567 -
majiayu000 Bundle Cto AuditPerform deep, expert-level codebase and architecture audits to identify technical strengths, weaknesses, risks, and opportunities. Use when a user asks for an assessment of a codebase's structure, quality, or readiness for scale. Deliver detailed, actionable, and prioritized recommendations grounded in engineering best practices.
567 -
majiayu000 Bundle Jsr AuditThis skill should be used when the user asks to 'audit for JSR', 'check JSR readiness', 'review JSR config', 'verify package for JSR', 'publish to JSR', 'prepare for JSR publishing', 'JSR compliance check', 'run JSR audit', or wants to ensure their Deno/TypeScript package meets JSR standards before publishing.
567 -
majiayu000 Bundle Map AuditFor leaders evaluating dashboards, metrics, or AI-generated reports to determine if they measure reality or generate confident-looking noise (Potemkin maps). Helps identify gaming potential, blind spots, and whether you should trust a metric more, less, or differently. Use when implementing new metrics, questioning existing dashboards, evaluating vendor claims, or when something feels off about your data. Keywords: dashboard audit, metrics, KPIs, gaming, Goodhart's law, AI reports, data quality, measurement validity, blind spots, Potemkin, are my metrics real, can I trust this data
567 -
majiayu000 Bundle PasswordsTop password lists for authorized security testing: common passwords, darkweb leaks, worst passwords. Curated essentials (<10MB).
567 -
majiayu000 Bundle Pr TriageContext-efficient PR comment triage. Evaluate, decide, act. Fix important issues, resolve the rest silently.
567 -
majiayu000 Bundle PrereviewReview unpushed commits before pushing for code quality, bugs, security issues, and error handling. Use when preparing to push commits, want pre-push code review, or need to validate changes before pushing. Runs comprehensive analysis using specialized review agents.
567 -
majiayu000 Bundle QA ChecksRun comprehensive quality verification including build, types, lint, tests, and security scans.
567 -
majiayu000 Bundle Rodriguez Threat Hunter PlaybookApply Roberto Rodriguez's threat hunting methodology with the Threat Hunter Playbook and HELK. Emphasizes documented hunts, open source infrastructure, and data-driven hunting. Use when building hunting programs or developing hunt playbooks.
567 -
majiayu000 Bundle Setup RlsConfigure Row Level Security policies for Supabase tables to control data access. Triggers when user mentions security, permissions, access control, or RLS policies.
567 -
majiayu000 Bundle Update KbSynchronize knowledge base documentation with current codebase implementation. Performs full, incremental, or targeted audits of source code and updates code maps, PRDs, patterns, SOPs, and user-facing docs to match reality. Use when: - After major refactors - Periodic maintenance (monthly) - Before starting new phase of work - When docs feel stale - User says "update kb", "sync docs", "audit docs"
567 -
majiayu000 Bundle MandelaAudit an evaluation, benchmark, or scoring harness for leakage, answering whether outside ground truth actually enters or the system is grading itself. Use when building or reviewing an eval or benchmark, or when the user says "is this eval leaking" or "check this benchmark for contamination". It reports where ground truth enters and where it does not, and it edits nothing.
567 -
majiayu000 Bundle Codex AbRun an A/B codex review experiment — holistic codex review vs 3 focused dimension passes (security, ecto, liveview) on the branch diff, classify findings, report a panel-value verdict. Use when the branch is fresh, before any codex review runs.
567 -
majiayu000 Bundle Dx AuditUse when auditing the developer-facing surface of a CLI, SDK, library, or package: API contracts, errors, CLI behavior, public types, onboarding, and config. Returns bounded, severity-tiered findings with root-cause analysis and committable fixes.
567 -
majiayu000 Bundle Ss AuditAudit screens for UX issues using Nielsen's heuristics and modern mobile UX best practices
567 -
majiayu000 Bundle AauthAAuth Laravel RBAC package implementation assistant
567 -
majiayu000 Bundle Ca PrOpen a pull request the only sanctioned way — clear every BLOCK-level review finding, then stage the PR. Never a direct write to the default branch.
567 -
majiayu000 Bundle NzismExpert New Zealand Information Security Manual (NZISM) advisor for NZ government agencies and their supply chains. Use for NZISM control guidance, gap analysis, agency security obligations, classification framework (Unclassified through Top Secret), security risk management, system certification, and GCSB/NCSC NZ compliance. Triggers on: NZISM controls, NZ government security, GCSB compliance, agency cybersecurity obligations, NZ classification markings, Restricted/Confidential/Secret system scoping, agency security policies, third-party supplier security, Certification and Accreditation (C&A), and any question about NZ government information security requirements or the NZISM framework.
567 -
majiayu000 Bundle OAUTHOAuth 2.0 and OpenID Connect implementation patterns. Use when implementing authentication, authorization flows, or integrating with OAuth providers like Google, GitHub, or custom identity providers.
567 -
majiayu000 Bundle ReconSecurity reconnaissance. USE WHEN recon, reconnaissance, bug bounty, attack surface. SkillSearch('recon') for docs.
567 -
majiayu000 Bundle SigmaCreate Sigma detection rules for SIEM log-based detection
567 -
majiayu000 Bundle TisaxExpert TISAX (Trusted Information Security Assessment Exchange) advisor for the automotive supply chain — the ENX/VDA assessment regime that OEMs like VW, BMW, and Mercedes-Benz require from suppliers and service providers. Covers the VDA ISA 6 catalogue (current through 2026) and the ISA2027 transition (published July 1, 2026; mandatory for assessments ordered from January 1, 2027), assessment levels AL1/AL2/AL3, all 12 assessment objectives/labels (Confidential, Strictly Confidential, High/Very High Availability, Proto Parts/Vehicles, Test Vehicles, Proto Events, Data, Special Data), maturity scoring (0–5, target 3, cutback rules), the ENX portal process, scoping, audit-provider selection, corrective action plans and the 9-month window, 3-year label validity, and ISO 27001 mapping. Use for any TISAX, VDA ISA, ENX, automotive information-security assessment, prototype protection, or OEM supplier-security requirement question — gap assessments, label selection, readiness, and audit prep.
567 -
majiayu000 Bundle TrivyThis skill should be used when scanning container images, filesystems, or repositories for vulnerabilities using Trivy. Use for CVE detection, security analysis, vulnerability comparison across image versions, understanding scan output (severity levels, status fields), and batch scanning multiple images.
567 -
majiayu000 Bundle AI EthicsImplement ethical AI practices and responsible AI governance. Use for: identifying and mitigating bias in datasets and models, ensuring fairness across demographic groups, implementing transparency and explainability requirements, protecting user privacy and data security, establishing accountability frameworks, conducting ethical impact assessments, complying with AI regulations (GDPR, EU AI Act), implementing human oversight mechanisms, and building trustworthy AI systems aligned with societal values.
567 -
majiayu000 Bundle API ReviewUse this skill to review public API changes, design new surfaces, audit consistency, and validate documentation completeness. Run it before any API release to confirm alignment with project guidelines.
567 -
majiayu000 Bundle Audit SpecAudit a checkpoint specification for realism and design decision forcing. Reviews specs to remove hand-holding, hidden corner cases, and architectural giveaways. Invoke with /audit-spec <problem> <checkpoint>.
567 -
majiayu000 Bundle Cfo WizardSmall business finance, tax strategy, and wealth management. Auto-activates for Augusta Rule, home office deduction, Solo 401k, R&D credits, tax optimization, Mercury/Ramp operations, Bitcoin treasury, IRS notices, audit defense, and bootstrapped founder CFO work.
567 -
majiayu000 Bundle Dma Attack TechniquesGuide for Direct Memory Access (DMA) attack techniques using FPGA hardware. Use this skill when researching PCIe DMA attacks, pcileech, FPGA firmware development, or hardware-based memory access for game security research.
567 -
majiayu000 Bundle Docs Audit> Triggers (ANY of these should invoke this skill):
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include eufy, pass, siem. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.